Hey @bytecodevm (eleven red pandas 🐼🐼🐼🐼🐼🐼🐼🐼🐼🐼🐼), got any spicy bytecode / VM / language implementation / JIT / music

Bagnes, Switzerland
eleven red pandas retweeted
⚠️CVE-2026-18963 (CVSS 9.1)⚠️ Critical Unauthenticated Account Takeover vulnerability in Keycloak’s reset-credentials flow. In affected Keycloak 26.x versions, unauthenticated attackers can bypass email verification during password recovery and continue the reset-credentials flow. This allows an attacker who knows a target username or email address to set new credentials without accessing the victim’s email, resulting in full account takeover. Patched versions include 26.4.15, 26.6.6, and 26.7.2. Users should upgrade to a fixed release. 🔥PoC + Vulnerable environment: github.com/EQSTLab/CVE-2026-… #Keycloak #AccountTakeover #AuthenticationBypass #PasswordReset #CWE640 #CyberSecurity #CVE #PoC #Exploit #CVE_2026_18963
6
47
315
27,108
eleven red pandas retweeted
Italian firm Dataflow Security, founded in 2019 by young hacker Luca Todesco, develops high-value exploits: including zero-click tools that break into computers and smartphones and has grown rapidly into a multimillion-euro supplier for governments and spyware makers. An investigation shows deep ties to Israel’s intelligence and military-cyber world: former senior Mossad official Eyal Tsir Cohen (shortlisted in 2025 to lead Shin Bet) now heads its two Israeli subsidiaries, while staff include veterans of Unit 8200 and former NSO Group employees. #osint irpimedia.irpi.eu/en-inside-…
5
54
304
81,577
40 лет назад погиб Клифф. Человек, который в общем-то и научил Металлику играть музыку.
10
24
212
8,983

ALT Well Done Laughing GIF

101
Limp bizzket sounds
こんばんワン
123
Super Happytime Death Machine
65
мёд
Replying to @oldLentach
Батя решил в героя поиграть,и как обычно в реальной жизни бывает,тупо сдох,за просто так,зачем идти за быдланом в догонку 🤦‍♂️
124
eleven red pandas retweeted
InjectSetConsole performs process code injection by leveraging a Windows named pipe. Unlike traditional techniques, it does not use the VirtualAllocEx and WriteProcessMemory APIs. #securityblog #cybersecurity zerosalarium.com/2026/09/edr…
12
76
5,219
eleven red pandas retweeted
iMessage EXR. zero click. heap overflow before the banner finishes. CVE-2026-86869. libAppleEXR sizes the buffer for 3 channels. 12 bytes. CompressedInterleave4 writes 4. 16 bytes. every pixel. three of those four bytes come from the file. BlastDoor never decodes EXR. Spotlight and the photo indexer do, later, with SDR hardcoded on. no tap. same ImageIO path on iPhone, iPad, and Mac. fixed in the 27 releases. older fleet still sits on it. credit: Niels Hofmans / ironPeak ironpeak.be/blog/ex-arrr-sai… #iOS #ExploitDev #InfoSec
12
30
200
19,910
eleven red pandas retweeted
Kernemul: Windows kernel driver and usermode app emulator for x86-64 and ARM64 targets. This can run on multiple host operating systems, such as Windows or Linux. AI was used for assisting development in this project, including the kernel handler implementations by noahware. Github: github.com/noahware/kernemul
3
15
162
7,892
Connor McGarr on ETW’s undocumented SecurityTrace bit: QUERY wants Antimalware-PPL, STOP does not, and a user-mode ControlTrace hook lets admin consume Threat-Intelligence without a driver. MSRC: not a CVE. core-jmp.org/2026/09/etw-sec… On 16 January 2026 Connor McGarr published a Windows-internals note, first on the Origin (by Prelude) blog, then on his own site. While building Origin’s Runtime Memory Protection preview, his team’s Antimalware-PPL ETW tooling could stop a trace session that had an undocumented SecurityTrace bit set — without Antimalware-PPL. That flag is supposed to keep such sessions (mostly Defender AutoLoggers) in the PPL club. Querying them as SYSTEM fails. #AutoLogger #ETW #kernel #MSRC #PPL #ProtectedProcess #Sechost #ThreatIntelligence #windows #WindowsInternals
122
Adam Chester’s SpecterOps research on disposable Mythic agents: from a vibe-coded abomination to a two-hour Oracle harness that one-shots stage-0 implants in Python, Go, Zig, C#, and Rust. YARA families rot. Hunt the protocol. core-jmp.org/2026/09/disposa… On 24 June 2026 Adam Chester, Senior Offensive Security Engineer on SpecterOps TRACE, published a 25-minute research post about disposable tooling: LLM-generated Mythic C2 agents that are cheap enough to throw away. The question was blunt: can you one-shot a new agent from an initial prompt to a tested, shippable implant with no human in the loop? #C2Frameworks #C2Infrastructure #Claude #ClaudeCode #CommandandControl(C2) #DisposableTooling #GPT #LLM #LLMassistedDevelopment #Mythic #redteam #RedTeamResearch #RedTeamTools #SpecterOps #YARA
1
102
Asim Manizada’s four Linux LPEs: DirtyAH6, TUNderflow, PPPoEject, DiagSpill. Decade-old bugs, userns for three, DiagSpill needs only SCTP. Patch 5.10.270 / 6.6.157 / 6.12.109 and cousins. PoCs on GitHub, VM-only. core-jmp.org/2026/09/linux-l… On 18 September 2026 Asim Manizada published four Linux local-root bugs found with the same agentic graph/geometry harness behind CIFSwitch, OVSwrap, and the “drunk LLM” kernel work. DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469). The underlying mistakes are 10–21 years old. The first three LPEs want unprivileged user namespaces (or equivalent CAP_NET_ADMIN in a userns-owned netns). DiagSpill does not. #CVE202668121 #CVE202674469 #CVE202680844 #CVE202681000 #DiagSpill #DirtyAH6 #IPsec #kernel #Linux #LinuxKernel #LinuxKernelExploitation #LinuxLPE #LocalPrivilegeEscalation(LPE) #PPPoE #PPPoEject #PrivilegeEscalation #SCTP #TUNderflow #UserNamespaces
112
eleven red pandas retweeted
装虚拟机最烦的不是系统本身,而是一堆配置项。 Quickemu 直接把流程简化了: 1️⃣ quickget 自动下载系统镜像并生成配置 2️⃣ quickemu 根据电脑硬件自动调整虚拟机参数 Windows、macOS、Linux 都能跑,官方还覆盖了大量系统版本,Win11 的 TPM 2.0 也不用自己折腾。 想测试其他系统,基本一条命令就能开搞。 Linux 用户可以收一个👇 🔗 github.com/quickemu-project/…
14
24
134
7,762
eleven red pandas retweeted
别再买昂贵的显卡了,这个项目把手头闲置的手机、平板、电脑组成一个 AI 计算集群 在GitHub 已斩获 4w+star 它把你所有设备的算力统一成一块虚拟 GPU,iPhone、iPad、Mac、树莓派,只要接在同一个局域网里就行 不用手动配置,自动发现节点,p2p 直连,所有推理都在本地跑 它会根据每台设备的实时性能和网络状况决定怎么切分模型,确保整体推理速度达到最优 有人实测用 4 台 M3 Ultra Mac Studio 跑起了 DeepSeek v3.1 671B,支持 RDMA over Thunderbolt 5 之后多机延迟降了 99%
6
43
338
27,462
eleven red pandas retweeted
Bunu görmeyen var mı? Dünyanın sonu geldiğinde kullanabileceğimiz bir repo çıkarmışlar. Survival computer İnternetsiz çalışan, içinde AI + Wikipedia + haritalar olan tam bağımsız bir bilgisayar sistemi. - Her şey lokalde çalışıyor (cloud yok, veri gönderme yok) - Tek komutla kuruluyor - Tarayıcıdan yönetiliyor - Aynı ağdaki tüm cihazlardan erişilebiliyor 👉 github.com/Crosstalk-Solutio… Umarım kullanmak zorunda kalmayız.... ----------------- Yapay zeka hakkında güncel kalmak için 👉 bakigul.substack.com
38
523
3,884
282,625
Excuse me, is your software already on the list of trusted applications?
Replying to @WildComputers
Try TMOG at tmog.org and pick the "Replace Windows Task Manager" option!
1
149
eleven red pandas retweeted
deGDID: Deletes all instances of Microsoft's GDID and prevents minting of new ones GitHub: github.com/yegors/deGDID
8
77
752
38,466